Description
A default VPC still needs subnets, routes, and security groups managed to meet organizational requirements. A default VPC is not inherently insecure, but relying on its initial configuration without review can leave unnecessary public paths.
aws_default_vpc manages the default VPC through Terraform. Its presence alone does not establish that workloads use the VPC or that network controls are absent.
Potential impact
- Insufficient network controls: unreviewed subnet, routing, or security group settings can permit unintended access.
- Inconsistent operations: network layouts may be harder to manage consistently across environments.
- Resource exposure: deployments that rely on defaults can include unnecessary public configurations.
Remediation
- Review the default VPC’s subnets, internet routes, and security groups, and apply the required controls.
- If separate network isolation is needed, define a dedicated VPC with
aws_vpcand design its subnets and access policies together. - Plan migration and connectivity before retiring or deleting a default VPC used by existing resources.
Examples
Manage the default VPC
hcl
resource "aws_default_vpc" "example" {
tags = {
Name = "Default VPC"
}
}
Define a separate VPC
hcl
resource "aws_vpc" "example" {
cidr_block = "10.0.0.0/16"
instance_tenancy = "default"
tags = {
Name = "main"
}
}
The first example manages the default VPC; the second defines a separate VPC. Declaring a separate VPC does not migrate existing resources or restrict access by itself. Configure subnets, routes, and security policies to suit the workload.